Insights · email deliverability

The Gmail and Yahoo bulk sender requirements are not why you are in spam

The rules only enforce what good senders already did. If spam placement arrived after February 2024, the fault was in the account long before.

A Gmail inbox open in Safari on a laptop, the Compose button and Primary tab showing beside the first sender names, warm lamplight behind the screen
Theo Tziapouras, founder and strategy at Engage Commerce
Theo TziapourasFounder and strategy
31 August 2026 1,412 words7 minute read
In short · six parts

Deliverability slid some time after February 2024 and somebody blamed the new rules. Fair guess. It's nearly always wrong, because the rules enforce standards published years earlier, so the account that fails them today was failing quietly long before.

Three sent Klaviyo campaign rows from one February, each naming buyer and engaged window segments in its send list, with open rate, click rate and revenue columns alongside

The rules did not break your deliverability, they exposed it

Open rates slid some time after February 2024 and somebody on the team blamed the new Gmail rules. Nearly every brand we've audited since said the same thing. Nearly every one was wrong, and the timing made it a fair guess, which is exactly why the story stuck.

Pull the account and we usually find the same pair of faults underneath. A list that hasn't had a genuine sunset pass in years, and a DKIM record that was never aligned to the sending domain. Often a trade show list that should never have been imported is sitting quietly under both.

It was already broken. Gmail and Yahoo didn't change what good email looks like, they stopped delivering bad email out of politeness. So the suppression list is the first thing we read on a new account.

What the rules actually ask, and how old every ask is

Since February 2024, anyone sending 5,000 or more emails a day to Gmail or Yahoo addresses has had to meet three conditions, and Google publishes them in its email sender guidelines. None of the three was invented for the occasion. Each one had been a published standard for years before anybody enforced it.

  • One-click unsubscribe on every marketing email, honoured promptly and never routed through a preferences maze
  • A spam complaint rate held under roughly three complaints in every thousand sends
  • SPF, DKIM and DMARC published, passing, and aligned with the domain your reader sees in the from line

That history decides where you look for the fault. Treat these as new rules and you bolt on an unsubscribe header and call it compliance. Treat them as standards you should already have met and you go hunting for the complaint rate nobody watched and the sunset pass nobody ran, which is closer to how we run email for Shopify brands.

The list nobody has cleaned is the actual fault

The usual account keeps every subscriber who ever signed up, going back years, because list size looks good in a board deck. Nobody wants to be the person who suppresses 40,000 addresses. So the file quietly fills with people who changed jobs, switched providers or forgot the brand entirely.

Mail those people and a slice of them hit the spam button instead of the unsubscribe link, because reporting spam is one click and finding the unsubscribe is two. The fix is the call our lifecycle strategy work starts with. Define engagement as opened or clicked inside a realistic window, then run everyone outside it through one honest win-back. Whoever ignores it gets suppressed, not deleted, and list size stops being the number anyone defends.

The segment names in those rows are the discipline in practice. Every send went to buyers and to a recent engagement window, not to one list called everyone. The audience is smaller on paper and the reputation grows, a trade the board deck never shows.

Records that exist are not records that align

Most teams tick the authentication box without knowing what the box checks. The requirement is alignment. The domain in your DKIM signature and the domain your SPF record authorises have to match the domain in your from address, at the organisational level. Records that merely exist in DNS can pass on their own and still fail the check that matters.

On a Klaviyo and Shopify stack the miss is nearly always the same one. The brand never set up a dedicated sending subdomain, stayed on the platform's shared default, and the signature ends up authenticating a domain that isn't theirs. DMARC scores the alignment, and that's the piece nobody rechecks after a migration or a platform switch.

CheckWhat passing actually proves
SPFThe server that sent the mail was allowed to send for that domain
DKIMThe message was signed and nothing altered it on the way
DMARCThe authenticated domain is the one the reader sees in the from line
AlignmentAll of it points at your domain, not your platform's shared one

Sorting it is an afternoon, not a project. Set up a dedicated sending subdomain, publish the records Klaviyo generates, start DMARC at p=none so the reports flow, and read the headers on a real send, not a preview tool. Then leave it alone and let the reputation build.

The complaint threshold is arithmetic, not mystery

Google's complaint threshold works out at roughly three complaints in every thousand sends. At 5,000 sends a day that's about 15 people choosing the spam button before your domain starts being treated as a risk. A competition list or a prize wheel spends that allowance faster than any subject line ever could.

Two women sitting in the sun against a drystone wall, each holding a coloured Thermos flask

Google Postmaster Tools shows the number directly once your domain is verified there, and Yahoo runs a complaint feedback loop of its own. The brands that get blindsided never looked until placement had already gone. The ones that catch it early keep complaint rate on the same dashboard as revenue per send, and check it weekly through autumn.

Don't let open rate carry the diagnosis on its own either. Apple's Mail Privacy Protection preloads images, so an open stopped meaning a reader years ago. Complaints, clicks and bounces are the honest columns left.

Run the audit in September, not after the peak send

  1. Pull the complaint rate from Google Postmaster Tools and Yahoo's feedback loop, and see how close to the threshold it actually sits
  2. Read the headers on a live send and confirm SPF and DKIM align with your from domain, not merely that records exist in DNS
  3. Find the date of your last genuine sunset pass, and if you have to think about it, that is the answer
  4. Segment the list by engagement window and face the share of it that has not opened or clicked anything in months
  5. Test that the unsubscribe really is one click, not a landing page with a confirm button, which fails the requirement

Most brands find the fault inside the first two items. Fix what you find in order and give it clean weeks to register, because reputation moves on evidence, not on effort. The peak send depends on every send before it, which is the whole argument for doing this now.

If the account needs more than an afternoon, this stops being a checklist and becomes the first month of a rebuild. Every account in our case studies started with exactly this read, before anyone discussed a campaign calendar.

Theo Tziapouras, founder and strategy at Engage Commerce

Theo Tziapouras

Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.

Do the Gmail and Yahoo bulk sender requirements apply to small senders?

The named conditions attach to anyone sending 5,000 or more emails a day to those providers, but the same authentication, complaint and unsubscribe signals decide placement for senders of every size. Meet them anyway and the threshold stops mattering.

Will one-click unsubscribe shrink my list?

It'll trim it, and that's a trade worth taking. Someone who wants out and can't find the door hits the spam button instead, which damages every future send to everyone else. An unsubscribe costs you one address. A complaint spends your standing with the mailbox provider.

Is DMARC worth publishing if I start at p=none?

Yes, because p=none still switches the reporting on, and the reports show whether SPF and DKIM genuinely align with your from domain on real sends. It satisfies the requirement itself too. Move to a stricter policy once the reports have run clean for a while.

Not got your answer?Chat to us
End matter

The flattering story and the true one

"The rules changed" is the version of events that lets everyone off the hook. The list stays the size it is, nobody explains the unchecked DKIM record, and the complaint rate keeps sitting wherever it sits. The true version is slower and a lot less flattering, and it was true long before February 2024. Gmail and Yahoo didn't raise the bar. They stopped carrying senders who never cleared it.

Theo TziapourasFounder and strategy · Engage Commerce

Would you rather this was just handled?

Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.

Engage CommerceTheo Tziapouras, founder of Engage Commerce

Book a call with our founder.

We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊